IN Brief:
- Kimsuky compromised South Korean groupware suppliers before moving into customer environments.
- Source code, configuration information, and trusted support relationships increased the attackers’ downstream reach.
- Defence manufacturers need controls that contain supplier compromise without disabling essential software and maintenance services.
A North Korean-linked Kimsuky campaign has compromised South Korean groupware suppliers and used information obtained inside those companies to target customer infrastructure.
Research by ENKI White Hat identified separate intrusions involving two vendors, including access through an externally exposed mail server and compromise of an employee workstation. Malware from the Gomir family was deployed as the attackers established persistence, surveyed internal systems, and collected configuration information.
Groupware platforms occupy a particularly useful position for espionage because they often span email, documents, approvals, calendars, directories, and internal collaboration. Suppliers may also retain customer deployment records, licence details, source code, remote-support tools, or credentials that reveal how downstream environments are built.
Once one of those vendors had been penetrated, information taken from its systems supported access to customer servers. A documented sequence began with entry into the supplier on 5 December 2025, movement into a development server by 8 December, and compromise of a customer server the following day.
That pace left little opportunity for the supplier to identify the initial breach before its customer relationships became useful to the attacker. It also shows why a vendor incident cannot be treated as a problem confined to the vendor’s own network.
Gomir provides familiar functions, including reconnaissance, command execution, file transfer, persistence, and data theft. Its strategic value in this campaign came from deployment context rather than exceptional novelty: a conventional backdoor installed inside a trusted supplier can expose several organisations at once.
Defence manufacturers often concentrate security investment around engineering networks, controlled technical information, and production systems, while business applications receive less attention. Yet groupware can contain programme schedules, supplier records, personnel information, travel plans, approval chains, and correspondence that support further targeting.
Development infrastructure carries still greater sensitivity. Access to source code can expose vulnerabilities, hard-coded credentials, update mechanisms, product architecture, and customer-specific functions. An attacker able to interfere with build or distribution systems could move beyond information theft and compromise software delivered downstream.
No poisoned software update has been identified in the disclosed incidents, but the possibility explains why secure development is becoming a defence-industrial requirement rather than an internal concern for software companies. Code signing, protected build environments, controlled administrator access, and independently retained logs all help determine whether a supplier can prove what happened.
Manufacturers should expect customers to ask more detailed questions about how vendors protect code, segregate development networks, approve releases, and monitor support accounts. A software bill of materials can identify components, although it cannot reveal whether a legitimate vendor administrator or build server has been compromised.
Contracts need to address that blind spot before an intrusion occurs. Incident-notification deadlines, evidence-retention obligations, audit rights, support-access limits, and responsibilities for downstream investigation should be clear enough to survive the first hours of a multi-company response.
Network architecture remains equally important. Groupware, help-desk tools, and remote-support services should not provide unrestricted movement into design, manufacturing, or operational-technology networks. Segmentation cannot prevent every compromise, but it can reduce the value of access obtained through a business application.
Identity controls should assume that a trusted supplier account may eventually be abused. Privileged access can be time-limited, approved for a specific task, constrained to defined systems, and recorded with enough detail to reconstruct activity later.
Recent disruption caused by PLA procurement bans across China’s military cyber supply chain exposed the risks created when defence organisations lose access to embedded security products, licences, and support. The Kimsuky campaign demonstrates the other side of the dependency: retaining a trusted supplier also carries risk when that supplier’s own infrastructure becomes hostile territory.
Smaller software vendors may struggle to fund the required assurance. Secure build systems, continuous monitoring, penetration testing, and dedicated incident-response staff carry costs that fragmented national markets do not always reward. Defence customers may need to pay for higher assurance instead of treating it as an uncompensated contractual obligation.
The same exposure reaches factory equipment. Production sites increasingly depend on vendor-managed applications for maintenance, quality, logistics, and machine connectivity, while remote access established for efficiency can bypass controls protecting the wider plant.
Resilience therefore requires more than selecting reputable suppliers. Organisations need an inventory of external access, tested procedures for revoking it, clean software copies, alternative support routes, and a clear view of which production systems would be affected if a vendor had to be disconnected.
Kimsuky’s use of groupware vendors turns inherited trust into an operational access route. For defence companies, the effective attack surface includes every software business, maintainer, cloud service, and support team allowed to operate inside the enterprise.
The practical response is not wholesale disconnection, but measurable assurance, limited privileges, and architecture designed to contain a supplier compromise before one vendor account becomes the shortest path into a sensitive programme.


